Falhas do tipo CWE-287

2.410 resultados

Autenticação Insuficiente ou Ausente

Quando um usuário ou sistema afirma ser quem diz que é, a aplicação não valida (ou valida mal) essa identidade antes de conceder acesso. Isso permite que um atacante se passe por outra pessoa sem fornecer credenciais válidas, obtendo privilégios indevidos.

Exemplo

Um sistema que aceita login apenas verificando um campo de e-mail na sessão (sem senha), ou uma API que confia em um identificador de usuário enviado no header HTTP sem validar um token assinado. Um atacante simplesmente muda o valor e acessa dados de terceiros.

Como mitigar

Implemente autenticação robusta: exija senha forte + MFA quando possível, valide tokens com assinatura criptográfica, revoque sessões expiradas, e nunca confie em dados controlados pelo cliente. Teste autenticação em cada endpoint crítico.

CVE-2024-50339CRITICALGLPI vulnerable to unauthenticated session hijackingEPSS 18.7%CVE-2025-58443CRITICALFOG's authentication bypass leads to full SQL DB dumpEPSS 18.5%CVE-2020-27838—A flaw was found in keycloak in versions prior to 13.0.0. The client registration endpoint allows fetching information about PUBLIC clients EPSS 17.9%CVE-2017-11151—A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitraryEPSS 16.3%CVE-2023-20238CRITICALA vulnerability in the single sign-on (SSO) implementation of Cisco BroadWorks Application Delivery Platform and Cisco BroadWorks Xtended SeEPSS 16.3%CVE-2018-1163—This vulnerability allows remote attackers to bypass authentication on vulnerable installations of Quest NetVault Backup 11.2.0.13. The specEPSS 16.0%CVE-2023-22501CRITICALAn authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate anoEPSS 15.5%CVE-2026-8181CRITICALBurst Statistics 3.4.0 - 3.4.1.1 - Authentication Bypass to Admin Account TakeoverEPSS 14.6%CVE-2021-24175—The Plus Addons for Elementor Page Builder < 4.1.7 - Authentication BypassEPSS 14.5%CVE-2024-49039HIGHWindows Task Scheduler Elevation of Privilege VulnerabilityEPSS 14.2%KEVCVE-2016-1908CRITICALThe client in OpenSSH before 7.2 mishandles failed cookie generation for untrusted X11 forwarding and relies on the local X11 server for accEPSS 13.7%CVE-2025-0890CRITICAL**UNSUPPORTED WHEN ASSIGNED** Insecure default credentials for the Telnet function in the legacy DSL CPE Zyxel VMG4325-B10A firmware versionEPSS 13.5%CVE-2023-20867LOWVMware Tools Authentication Bypass VulnerabilityEPSS 13.5%KEVCVE-2026-46817CRITICALVulnerability in the Oracle Payments product of Oracle E-Business Suite (component: File Transmission). Supported versions that are affecteEPSS 13.0%KEVCVE-2024-21410CRITICALMicrosoft Exchange Server Elevation of Privilege VulnerabilityEPSS 12.6%KEVCVE-2021-26117—ActiveMQ: LDAP-Authentication does not verify passwords on servers with anonymous bindEPSS 11.3%CVE-2025-52376CRITICALAn authentication bypass vulnerability in the /web/um_open_telnet.cgi endpoint in Nexxt Solutions NCM-X1800 Mesh Router firmware UV1.2.7 andEPSS 11.2%CVE-2026-42018HIGHAnonymous user token generation exposure in JFrog ArtifactoryEPSS 11.0%KEVCVE-2026-65400CRITICALAn authentication issue was addressed with improved state management. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.7.9, macEPSS 10.5%KEVCVE-2021-24647—Pie Register < 3.7.1.6 - Unauthenticated Arbitrary LoginEPSS 9.8%